PT-2026-44936 · Dokploy · Dokploy

·

CVE-2026-45632

·

Published

2026-05-29

·

Updated

2026-08-10

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dokploy versions prior to 0.26.8
Description Dokploy is a self-hostable Platform as a Service (PaaS) where the schedule router fails to enforce organization or role checks. This allows any authenticated user to create, update, run, or delete schedules belonging to other organizations by providing the scheduleId or serverId. Because schedule types server and dokploy-server write and execute scripts on the host or remote servers, this can lead to Remote Code Execution (RCE), which is the ability to execute arbitrary commands on a target machine.
Recommendations Update to a version later than 0.26.7.

Exploit

Fix

RCE

Missing Authorization

Improper Privilege Management

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45632
GHSA-7WMR-57MG-H5Q6

Affected Products

Dokploy